CVE-2026-17090

Beaver Builder Page Builder <= 2.10.2.2 - Authenticated (Author+) Stored Cross-Site Scripting via Button Module 'button' Parameter

The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Button Module 'button' (Button Code) Setting in all versions up to, and including, 2.10.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Beaver Builder grants editor access to any WordPress role holding the edit_posts capability by default, meaning Author-level users and above can exploit this vulnerability.


We have discovered 20,557 live websites that are affected by CVE-2026-17090.

Run a Free Instant Scan




Affected Software

Product  Beaver Builder Lite
Category Wordpress Plugins
Vulnerable Domains20,557 live websites (100% of Beaver Builder Lite install base)
Vulnerable Versions
  • from 0 through 2.10.2.2
Vulnerable Versions Count96 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 15, 2026
  • Updated - Aug 17, 2026

Credits

  • a1batr0ss (finder)

Website Distribution by Country

Number of websites using CVE-2026-17090
United States13,107 websites



Germany1,088 websites
GB775 websites
Canada686 websites
France518 websites
Netherlands431 websites
Australia359 websites
Italy292 websites
Poland223 websites
Cyprus203 websites

Website Distribution by TLD

Number of websites using CVE-2026-17090
.com12,428 websites
.org1,840 websites
.net607 websites
.de574 websites
.co.uk482 websites
.ca476 websites
.nl395 websites
.com.au336 websites
.fr210 websites
.it192 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-17090

Top websites that are affected by CVE-2026-17090. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****************.com United States*,***
**********.se Sweden**,***
*********************************.org United States**,***
***.org United States**,***
******.net United States**,***
********.ch Switzerland**,***
******.com United States**,***
******.tv United States**,***
************.com United States***,***
*****.org United States***,***
See full domain list

FAQ

CVE-2026-17090 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Beaver Builder Lite
A total of 20,557 websites have been identified as vulnerable to CVE-2026-17090, based on global website indexing conducted by WebTechSurvey.
The Beaver Builder Lite is affected by the CVE-2026-17090 vulnerability.
Beaver Builder Lite versions up to and including 2.10.2.2 are vulnerable to CVE-2026-17090.

References